WebAPI/Security/Bluetooth: Difference between revisions

no edit summary
No edit summary
No edit summary
Line 10: Line 10:
Inherent threats: Privacy, access to sensitive user devices, de-anonimization based on bluetooth state
Inherent threats: Privacy, access to sensitive user devices, de-anonimization based on bluetooth state


Threat severity: high
Threat severity: High


== Regular web content (unauthenticated) ==
== Regular web content (unauthenticated) ==
Line 21: Line 21:
Potential mitigations:
Potential mitigations:


== Trusted (authenticated by publisher) ==
== Privileged (approved by app store) ==
Use cases: None
Use cases: None


Line 28: Line 28:
Potential mitigations:
Potential mitigations:


== Certified (vouched for by trusted 3rd party) ==
== Certified (system-critical apps) ==
Use cases:
Use cases:
*Read bluetooth adapter state
*Read bluetooth adapter state
Confirmed users
717

edits